2024-12-03 ┃ edited ┃ RE: pid_eins
It will even optionally convert your DER certificate into the ESL format EFI SB expects.
Or in other words: running a self-enrolled system has become a lot more automatic now. If you focus on building images for VMs it might make a lot of sense to make self-enrolled systems a thing, and thus ensure that your VMs only run your code and nothing else, locking them down substantially.
And that's it for today.
https://mastodon.social/@pid_eins/113587917662484775
@pid_eins Can this be used in an "append-only" way? That is, without wiping out existing enrolled keys?
@pid_eins Can this be done with containers as well?
────
────